Known vulnerabilities in IBM DB2 - page 10

Software: IBM DB2
Software CPE: cpe:2.3:a:ibm_corporation:ibm_db2:*:*:*:*:*:*:*:*
Total vulnerabilities: 239
Public exploits: 10
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM DB2 IBM DB2 is affected by 239 known vulnerabilities: 1 critical, 21 high, 132 medium, 85 low Critical High Medium Low

Vulnerabilities (239)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75494 - Improper input validation
CVE-2023-29255
CWE-20 Medium
No
No
- 25.04.2023 SB2023042561
SB2023050912
SB2023053014
and 7 more
#VU75493 - Permissions, Privileges, and Access Controls
CVE-2023-29257
CWE-264 Low
No
No
- 25.04.2023 SB2023042561
SB2023050912
SB2023053014
and 8 more
#VU75479 - Resource exhaustion
CVE-2023-25930
CWE-400 Medium
No
No
10.5.0.11, 11.1.4.7, 11.5.7, 11.5.8 25.04.2023 SB2023042530
SB2023050912
SB2023053014
and 8 more
#VU72060 - Information Exposure Through Log Files
CVE-2022-43930
CWE-532 Low
No
No
- 08.02.2023 SB2023020862
SB2023032013
SB2023060713
and 6 more
#VU72059 - Improper Privilege Management
CVE-2022-43927
CWE-269 Low
No
No
- 08.02.2023 SB2023020862
SB2023032013
SB2023060713
and 7 more
#VU72058 - Resource exhaustion
CVE-2022-43929
CWE-400 Low
No
No
- 08.02.2023 SB2023020862
SB2023032013
SB2023060713
and 7 more
#VU69507 - Improper Privilege Management
CVE-2022-22483
CWE-269 Low
No
No
11.5.8 22.11.2022 SB2022112251
SB2023012308
#VU67214 - Improper input validation
CVE-2022-35637
CWE-20 Medium
No
No
10.5.0.11, 11.1.4.7, 11.5.8 13.09.2022 SB2022091321
SB2023012308
#VU64650 - Exposure of sensitive information to an unauthorized actor
CVE-2022-22390
CWE-200 Low
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7, 11.5.7 24.06.2022 SB2022062419
SB2022082224
SB2023040617
#VU64634 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-22389
CWE-89 Low
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7, 11.5.7 24.06.2022 SB2022062405
SB2022082224
SB2023040617
#VU60739 - Integer overflow
CVE-2022-25315
CWE-190 High
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 99 more
#VU60738 - Integer overflow
CVE-2022-25314
CWE-190 Medium
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 68 more
#VU60737 - Stack-based buffer overflow
CVE-2022-25313
CWE-121 High
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 64 more
#VU60736 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-25235
CWE-94 High
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 106 more
#VU60733 - Improper input validation
CVE-2022-25236
CWE-20 Medium
No
No
9.7.0.11, 10.1.0.6, 10.5.0.11, 11.1.4.7 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 109 more
#VU59098 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44832
CWE-94 Medium
No
No
11.5.6.0, 11.5.7.0 28.12.2021 SB2021122816
SB2021123002
SB2022010601
and 197 more
#VU57487 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2021-35550
CWE-300 Medium
No
No
7.0.11.0, 8.0.7.5 19.10.2021 SB2021101939
SB2021101940
SB2021102101
and 102 more
#VU57496 - Improper input validation
CVE-2021-35603
CWE-20 Low
No
No
7.0.11.0, 8.0.7.5 19.10.2021 SB2021101939
SB2021101940
SB2021102101
and 112 more
#VU57150 - Improper Certificate Validation
CVE-2014-3577
CWE-295 Low
No
No
11.5.8 08.10.2021 SB2014082106
SB2021100807
SB2023020872
and 24 more
#VU55060 - Improper input validation
CVE-2021-2341
CWE-20 Low
No
No
7.0.11.0, 8.0.7.5 20.07.2021 SB2021072054
SB2021072055
SB2021072201
and 72 more


Showing elements 181 - 200 out of 239